Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
The US Bureau of Industry and Security issued a final rule (RIN 0694-AK74, 91 FR 17851, FR doc 2026-06851, signed 7 April 2026, published 9 April 2026, effective 7 April 2026) extending two compliance dates in the January 2025 Foundry Due Diligence (FDD) interim final rule that introduced the "Authorized IC Designer" / "Approved IC Designer" framework for advanced-computing integrated circuits controlled under ECCN 3A090.a. The prior 13 April 2026 cutoff for Authorized IC Designer status — the self-certification pathway available to designers headquartered in Country Group A:1 / A:5 / Taiwan and not parented in Macau or D:5 — is moved to 31 December 2026, and the application window to become an Approved IC Designer is extended to the same date with a subsequent 180-day authorization runway. The rule is a procedural deadline-extension only; it does not change the substantive scope, eligibility criteria, ECCN classifications, or end-use / end-user restrictions of the FDD IFR.
Indonesia's Ministry of Communications and Digital Affairs (Kemkomdigi) promulgated Permenkomdigi No. 5/2025 on 25 March 2025 as the implementing regulation under Government Regulation PP 71/2019 governing Public-Scope Electronic System Operators (PSE Lingkup Publik), defined as operators running electronic systems for government institutions or critical public services. The regulation mandates registration, data classification by risk level (low/medium/ high/strategic) with corresponding domestic storage and processing requirements, content- moderation governance, and access-blocking mechanisms for prohibited electronic information. All public-scope PSEs must achieve compliance by 25 March 2026, with non-compliant operators subject to progressive administrative sanctions under Articles 100-series ranging from written warnings to access disconnection (pemutusan akses) and removal from official registries.
The Cyberspace Administration of China (CAC) issued the Provisions on Promoting and Regulating Cross-Border Data Flows (《促进和规范数据跨境流动规定》) on 22 March 2024, effective immediately. The rules substantially raise the thresholds at which CAC security assessment, Standard Contractual Clauses (SCC), or Personal Information Protection Certification are required for outbound data transfers, and create categorical exemptions for contract performance, HR management, intra-group transfers below a volume threshold, and transit data processed in China with no domestic personal information introduced. A Free Trade Zone pilot mechanism allows designated FTZs (Shanghai Lingang, Tianjin, Beijing) to publish their own negative lists defining which data categories still require prior approval, easing conditions for multinationals with operations in those zones.
On December 15, 2023, BIS published a procedural notice (88 FR 86821) extending the public comment deadline for two major October 25, 2023 interim final rules: the Semiconductor Manufacturing Items IFR (88 FR 73424) and the Advanced Computing / Supercomputer Semiconductor End-Use IFR (88 FR 73458). The original comment deadline of December 18, 2023 was extended by 30 days to January 17, 2024, to allow stakeholders additional time to review the complex regulatory changes and submit substantive input. The document contains no amendments to the Export Administration Regulations (EAR) and no changes to export-control parameters.
BIS amended §§ 734.15 and 734.19 of the Export Administration Regulations (EAR) to clarify that a "release of software" for purposes of the transfer-of-access-information provision includes both source code and object code. A cross-reference was also added from § 734.15 to § 734.19. The practical effect is that providing a decryption key, password, or other access credential to a foreign person to unlock controlled software requires an export licence to the same degree as exporting the software itself would.
Regulation (EU) 2022/1925 of the European Parliament and of the Council of 14 September 2022 on contestable and fair markets in the digital sector (Digital Markets Act, DMA) was published in OJ L 265 on 12 October 2022, entered into force on 1 November 2022, and applied for the most part from 2 May 2023. The DMA establishes an ex-ante competition framework imposing binding obligations and prohibitions on designated "gatekeepers" operating Core Platform Services (CPS) in the EU — covering search engines, social-networking services, video-sharing platforms, number-independent interpersonal communications, operating systems, web browsers, virtual assistants, cloud computing, online intermediation services, and online advertising. The European Commission designated six gatekeepers on 6 September 2023 (Alphabet, Amazon, Apple, ByteDance, Meta, Microsoft); full compliance with all obligations was required by 7 March 2024. Subsequent designations added Booking.com (May 2024) and Apple iPadOS (April 2024). The DMA functions as the EU's structural anchor for ex-ante digital competition regulation, closing the enforcement gap left by ex-post competition law (Articles 101–102 TFEU) where market-tipping dynamics make remedies ineffective after the fact.
The Income Tax (Amendment) Act, 2021 (Act No. 43 of 2021), assented 30 December 2021 and in force from 1 January 2022, re-introduces the deductibility of Mineral Royalty Tax (MRT) paid under the Mines and Minerals Development Act, 2015 when computing a mining company's taxable income for corporate income tax purposes. The Act removes mineral royalty from the list of non-deductible expenditures in section 44 of the Income Tax Act, reversing a non-deductibility rule that had applied since a 2015-era amendment and that mining companies and industry stakeholders had argued produced double taxation of the same revenue stream. Deductibility is conditional on the royalty having actually been paid for the charge year.
The Personal Information Protection Law of the People's Republic of China (中华人民共和国个人信息保护法 — PIPL) was adopted at the 30th meeting of the 13th NPC Standing Committee on 20 August 2021 and entered into force on 1 November 2021, constituting the third and final pillar of China's cybersecurity and data-governance regulatory trinity alongside the Cybersecurity Law (2016) and the Data Security Law (2021). The PIPL is China's comprehensive personal-information statute establishing consent-based and necessity-based legal bases for PI processing, a tiered cross-border personal-data transfer regime (CAC security assessment / PI protection certification / Standard Contractual Clauses), extraterritorial application (Art. 3) to non-Chinese controllers offering services to or analysing the behaviour of PRC residents, and a heightened protection regime for sensitive personal information and data of minors under 14. It mandates data-protection impact assessments, personal-information-protection-officer obligations at designated handlers, breach notification, and a full suite of data-subject rights including access, rectification, deletion, portability, objection, and automated- decision-making opt-out. Article 53 requires overseas controllers to establish a domestic representative or designated entity in China, providing a domestic enforcement counterparty.
The Data Security Law of the People's Republic of China (中华人民共和国数据安全法) was adopted at the 29th meeting of the 13th NPC Standing Committee on 10 June 2021 and entered into force on 1 September 2021, constituting the second pillar of China's cybersecurity and data-governance regulatory trinity alongside the Cybersecurity Law (2016) and the Personal Information Protection Law (2021). The DSL establishes a tiered data-classification regime — "important data" and "national core data" — with escalating security obligations including risk assessment, risk monitoring, breach reporting, and classified-protection requirements for data handlers. It introduces a data-export security review for "important data" generated or collected within China, the statutory parent authority operationalised by the 2024 CAC Cross-Border Data Flow Provisions, and enacts a §36 blocking statute prohibiting Chinese organisations and individuals from transferring data stored in China to foreign judicial or law-enforcement authorities without prior PRC government approval.
The Cybersecurity Law of the People's Republic of China (中华人民共和国网络安全法) was adopted at the 24th meeting of the 12th NPC Standing Committee on 7 November 2016 and entered into force on 1 June 2017, establishing the foundational legal framework for network security governance across all sectors. The law creates the Critical Information Infrastructure Operator (CIIO) designation and protection regime administered by the Cyberspace Administration of China (CAC), mandates data localisation for personal information and important data collected or generated by CIIOs in China, and establishes cross-border data-transfer security assessment requirements under Article 37 — the provision later operationalised by DSL 2021, PIPL 2021, and the 2024 CAC Cross-Border Data Flow Provisions. The CSL introduced multi-level protection scheme (等级保护制度 / MLPS) obligations for all network operators and network-product/service security-review procedures, under which CAC triggered the cybersecurity review of Didi Global in 2021 and the exclusion of Micron's products from Chinese critical-infrastructure projects in 2023.
Japan's Foreign Exchange and Foreign Trade Act (FEFTA, Act No. 228 of 1 December 1949; 外国為替及び外国貿易法) is the foundational umbrella statute governing the entire modern Japanese economic-statecraft toolkit. Originally a restrictive positive-list regime for foreign-exchange transactions, FEFTA was fundamentally liberalised by the 1980 revision (positive-list to negative-list shift) and again overhauled in 1998 to establish the modern regulatory architecture. Three principal enforcement arms operate under FEFTA: (i) security export controls administered by METI via the Export Trade Control Order and the Foreign Exchange Order (covering the Wassenaar Arrangement, Australia Group, MTCR, NSG, and CWC controlled-items lists plus Japan-specific catch-all controls); (ii) inward FDI screening administered jointly by the Ministry of Finance and sector ministries (prior notification and pre-notification regime, substantially expanded 2019–2020 with Core Business Sectors covering semiconductors, critical minerals, advanced materials, cloud computing, and aerospace added 2021); and (iii) autonomous economic sanctions (asset- freeze and payment-restriction designations against Russia, Iran, DPRK, Myanmar, Belarus, and others via Cabinet Orders made under FEFTA authority). Structurally peer-foundational to the US Trade Expansion Act 1962, US Trade Act 1974, UK SAMLA 2018, CN Export Control Law 2020, and CN Anti-Foreign Sanctions Law 2021 as the G7+CN foundational economic- statecraft statute cluster.